package jdbc;

import java.sql.*;

/**
 * 预编译SQL
 * 预编译SQL允许我们使用"?"对SQL"值"
 */
public class Demo8 {
    public static void main(String[] args) {
        try (Connection conn = DBUtil.getConnection();){
            Statement statement = conn.createStatement();
            String sql = "SELECT id,username,password,nickname,age "+
                         "FROM user "+
                         "WHERE username=? AND password=?";
            PreparedStatement ps = conn.prepareStatement(sql);
            ps.setString(1,"范传奇");
            ps.setString(2,"123456");
            ResultSet rs = ps.executeQuery();
            if (rs.next()){
                System.out.println("登录成功");
            }else {
                System.out.println("登录失败");
            }
        } catch (SQLException e) {
            e.printStackTrace();
        }

    }
}
